---
title: "Screening sources manifest: sanctions and PEP source lists, per-source staleness (max_age_hours), attribution, and covered regimes"
method: GET
path: "/api/v1/entity/sources"
tags: ["Sugra Entity"]
---

# Screening sources manifest: sanctions and PEP source lists, per-source staleness (max_age_hours), attribution, and covered regimes

`GET /api/v1/entity/sources`

Source configuration and coverage manifest for the entity-screening corpus: which sanctions and PEP source lists are loaded, each list's freshness and staleness threshold (max_age_hours), per-source attribution and provenance under its public reuse terms, the covered sanctions regimes (covered_regimes), and an explicit statement of what is not covered. Use it to inspect source configuration, list freshness, and whether a regime such as US OFAC SDN (ofac_sdn) is in scope before screening. A metadata endpoint: it reports loaded state (always 200), never a screening verdict.

## Response `200`

Successful Response

- unknown

## Other responses

- `401` — Missing or invalid `x-api-key` header. JSON body with a stable `code` distinguishing `missing_api_key` (no header sent) from `invalid_api_key` (header sent, key not accepted); any other 401 source carries the generic `unauthorized` with its detail as `reason`. Plus `hint`. `plan` is always null on 401 - an unauthenticated request has no plan; quota exhaustion is 429, not 401.
- `429` — Daily rate limit exceeded. Check `X-RateLimit-Reset` for the next window.
- `503` — Upstream source is temporarily unavailable. Retry after a short delay.

---

[API](https://skmtc.net/sugra/apis/sugra-api.md) · [All operations](https://skmtc.net/sugra/apis/sugra-api/llms.txt) · [OpenAPI document](https://skmtc-service-staging.skmtc.workers.dev/v1/apis/sugra/sugra-api/versions/4c4530760ba1/schema)
